Scientific Linux Security Update : tigervnc and fltk on SL7.x x86_64

Description

FLTK (pronounced 'fulltick') is a cross-platform C++ GUI toolkit. It provides modern GUI functionality without the bloat, and supports 3D graphics via OpenGL and its built-in GLUT emulation.

The following packages have been upgraded to a later upstream version:
tigervnc (1.8.0), fltk (1.3.4).

Security Fix(es) :

A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)

A double free flaw was found in the way TigerVNC handled ClientFence messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientFence messages, resulting in denial of service. (CVE-2017-7393)

A missing input sanitization flaw was found in the way TigerVNC handled credentials. A remote unauthenticated attacker could use this flaw to make Xvnc crash by sending specially crafted usernames, resulting in denial of service. (CVE-2017-7394)

An integer overflow flaw was found in the way TigerVNC handled ClientCutText messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientCutText messages, resulting in denial of service. (CVE-2017-7395)

A buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service. (CVE-2017-5581)

A memory leak flaw was found in the way TigerVNC handled termination of VeNCrypt connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion. (CVE-2017-7392)

A memory leak flaw was found in the way TigerVNC handled client connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion. (CVE-2017-7396)

#
# (C) Tenable Network Security, Inc.
#
# The descriptive text is (C) Scientific Linux.
#
include("compat.inc");
if (description)
{
script_id(102658);
script_version("$Revision: 3.1 $");
script_cvs_date("$Date: 2017/08/22 13:51:45 $");
script_cve_id("CVE-2016-10207", "CVE-2017-5581", "CVE-2017-7392", "CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7395", "CVE-2017-7396");
script_name(english:"Scientific Linux Security Update : tigervnc and fltk on SL7.x x86_64");
script_summary(english:"Checks rpm output for the updated packages");
script_set_attribute(
attribute:"synopsis",
value:
"The remote Scientific Linux host is missing one or more security
updates."
);
script_set_attribute(
attribute:"description",
value:
"FLTK (pronounced 'fulltick') is a cross-platform C++ GUI toolkit. It
provides modern GUI functionality without the bloat, and supports 3D
graphics via OpenGL and its built-in GLUT emulation.
The following packages have been upgraded to a later upstream version:
tigervnc (1.8.0), fltk (1.3.4).
Security Fix(es) :
- A denial of service flaw was found in the TigerVNC's
Xvnc server. A remote unauthenticated attacker could use
this flaw to make Xvnc crash by terminating the TLS
handshake process early. (CVE-2016-10207)
- A double free flaw was found in the way TigerVNC handled
ClientFence messages. A remote, authenticated attacker
could use this flaw to make Xvnc crash by sending
specially crafted ClientFence messages, resulting in
denial of service. (CVE-2017-7393)
- A missing input sanitization flaw was found in the way
TigerVNC handled credentials. A remote unauthenticated
attacker could use this flaw to make Xvnc crash by
sending specially crafted usernames, resulting in denial
of service. (CVE-2017-7394)
- An integer overflow flaw was found in the way TigerVNC
handled ClientCutText messages. A remote, authenticated
attacker could use this flaw to make Xvnc crash by
sending specially crafted ClientCutText messages,
resulting in denial of service. (CVE-2017-7395)
- A buffer overflow flaw, leading to memory corruption,
was found in TigerVNC viewer. A remote malicious VNC
server could use this flaw to crash the client vncviewer
process resulting in denial of service. (CVE-2017-5581)
- A memory leak flaw was found in the way TigerVNC handled
termination of VeNCrypt connections. A remote
unauthenticated attacker could repeatedly send
connection requests to the Xvnc server, causing it to
consume large amounts of memory resources over time, and
ultimately leading to a denial of service due to memory
exhaustion. (CVE-2017-7392)
- A memory leak flaw was found in the way TigerVNC handled
client connections. A remote unauthenticated attacker
could repeatedly send connection requests to the Xvnc
server, causing it to consume large amounts of memory
resources over time, and ultimately leading to a denial
of service due to memory exhaustion. (CVE-2017-7396)"
);
# http://listserv.fnal.gov/scripts/wa.exe?A2=ind1708&L=scientific-linux-errata&F=&S=&P=17357
script_set_attribute(
attribute:"see_also",
value:"http://www.nessus.org/u?a7ec1ab5"
);
script_set_attribute(attribute:"solution", value:"Update the affected packages.");
script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P");
script_set_cvss3_base_vector("CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H");
script_set_attribute(attribute:"plugin_type", value:"local");
script_set_attribute(attribute:"cpe", value:"x-cpe:/o:fermilab:scientific_linux");
script_set_attribute(attribute:"patch_publication_date", value:"2017/08/01");
script_set_attribute(attribute:"plugin_publication_date", value:"2017/08/22");
script_end_attributes();
script_category(ACT_GATHER_INFO);
script_copyright(english:"This script is Copyright (C) 2017 Tenable Network Security, Inc.");
script_family(english:"Scientific Linux Local Security Checks");
script_dependencies("ssh_get_info.nasl");
script_require_keys("Host/local_checks_enabled", "Host/cpu", "Host/RedHat/release", "Host/RedHat/rpm-list");
exit(0);
}
include("audit.inc");
include("global_settings.inc");
include("rpm.inc");
if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
release = get_kb_item("Host/RedHat/release");
if (isnull(release) || "Scientific Linux " &gt;!&lt; release) audit(AUDIT_HOST_NOT, "running Scientific Linux");
if (!get_kb_item("Host/RedHat/rpm-list")) audit(AUDIT_PACKAGE_LIST_MISSING);
cpu = get_kb_item("Host/cpu");
if (isnull(cpu)) audit(AUDIT_UNKNOWN_ARCH);
if (cpu &gt;!&lt; "x86_64" && cpu !~ "^i[3-6]86$") audit(AUDIT_LOCAL_CHECKS_NOT_IMPLEMENTED, "Scientific Linux", cpu);
flag = 0;
if (rpm_check(release:"SL7", cpu:"x86_64", reference:"fltk-1.3.4-1.el7")) flag++;
if (rpm_check(release:"SL7", cpu:"x86_64", reference:"fltk-debuginfo-1.3.4-1.el7")) flag++;
if (rpm_check(release:"SL7", cpu:"x86_64", reference:"fltk-devel-1.3.4-1.el7")) flag++;
if (rpm_check(release:"SL7", cpu:"x86_64", reference:"fltk-fluid-1.3.4-1.el7")) flag++;
if (rpm_check(release:"SL7", cpu:"x86_64", reference:"fltk-static-1.3.4-1.el7")) flag++;
if (rpm_check(release:"SL7", cpu:"x86_64", reference:"tigervnc-1.8.0-1.el7")) flag++;
if (rpm_check(release:"SL7", cpu:"x86_64", reference:"tigervnc-debuginfo-1.8.0-1.el7")) flag++;
if (rpm_check(release:"SL7", reference:"tigervnc-icons-1.8.0-1.el7")) flag++;
if (rpm_check(release:"SL7", reference:"tigervnc-license-1.8.0-1.el7")) flag++;
if (rpm_check(release:"SL7", cpu:"x86_64", reference:"tigervnc-server-1.8.0-1.el7")) flag++;
if (rpm_check(release:"SL7", reference:"tigervnc-server-applet-1.8.0-1.el7")) flag++;
if (rpm_check(release:"SL7", cpu:"x86_64", reference:"tigervnc-server-minimal-1.8.0-1.el7")) flag++;
if (rpm_check(release:"SL7", cpu:"x86_64", reference:"tigervnc-server-module-1.8.0-1.el7")) flag++;
if (flag)
{
if (report_verbosity &gt; 0) security_warning(port:0, extra:rpm_report_get());
else security_warning(0);
exit(0);
}
else audit(AUDIT_HOST_NOT, "affected");

All product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement.If you are an owner of some content and want it to be removed, please mail to content@vulners.com Vulners, 2017

{"result": {"cve": [{"id": "CVE-2017-5581", "type": "cve", "title": "CVE-2017-5581", "description": "Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer boundaries.", "published": "2017-02-28T13:59:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5581", "cvelist": ["CVE-2017-5581"], "lastseen": "2018-01-05T11:53:13"}, {"id": "CVE-2016-10207", "type": "cve", "title": "CVE-2016-10207", "description": "The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.", "published": "2017-02-28T13:59:00", "cvss": {"score": 5.0, "vector": "AV:NETWORK/AC:LOW/Au:NONE/C:NONE/I:NONE/A:PARTIAL/"}, "href": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-10207", "cvelist": ["CVE-2016-10207"], "lastseen": "2018-02-02T11:36:39"}, {"id": "CVE-2017-7393", "type": "cve", "title": "CVE-2017-7393", "description": "In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.", "published": "2017-03-31T22:59:00", "cvss": {"score": 6.5, "vector": "AV:NETWORK/AC:LOW/Au:SINGLE_INSTANCE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7393", "cvelist": ["CVE-2017-7393"], "lastseen": "2018-01-13T11:28:34"}, {"id": "CVE-2017-7394", "type": "cve", "title": "CVE-2017-7394", "description": "In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames.", "published": "2017-03-31T22:59:00", "cvss": {"score": 5.0, "vector": "AV:NETWORK/AC:LOW/Au:NONE/C:NONE/I:NONE/A:PARTIAL/"}, "href": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7394", "cvelist": ["CVE-2017-7394"], "lastseen": "2018-01-13T11:28:34"}, {"id": "CVE-2017-7392", "type": "cve", "title": "CVE-2017-7392", "description": "In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.", "published": "2017-03-31T22:59:00", "cvss": {"score": 5.0, "vector": "AV:NETWORK/AC:LOW/Au:NONE/C:NONE/I:NONE/A:PARTIAL/"}, "href": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7392", "cvelist": ["CVE-2017-7392"], "lastseen": "2018-01-13T11:28:34"}, {"id": "CVE-2017-7395", "type": "cve", "title": "CVE-2017-7395", "description": "In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.", "published": "2017-03-31T22:59:00", "cvss": {"score": 4.0, "vector": "AV:NETWORK/AC:LOW/Au:SINGLE_INSTANCE/C:NONE/I:NONE/A:PARTIAL/"}, "href": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7395", "cvelist": ["CVE-2017-7395"], "lastseen": "2018-01-13T11:28:34"}, {"id": "CVE-2017-7396", "type": "cve", "title": "CVE-2017-7396", "description": "In TigerVNC 1.7.1 (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server.", "published": "2017-03-31T22:59:00", "cvss": {"score": 5.0, "vector": "AV:NETWORK/AC:LOW/Au:NONE/C:NONE/I:NONE/A:PARTIAL/"}, "href": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7396", "cvelist": ["CVE-2017-7396"], "lastseen": "2018-01-13T11:28:34"}], "gentoo": [{"id": "GLSA-201702-19", "type": "gentoo", "title": "TigerVNC: Buffer overflow", "description": "### Background\n\nTigerVNC is a high-performance VNC server/client.\n\n### Description\n\nA buffer overflow vulnerability in ModifiablePixelBuffer::fillRect in vncviewer was found. \n\n### Impact\n\nA remote attacker, utilizing a malicious VNC server, could execute arbitrary code with the privileges of the user running the client or cause a Denial of Service condition. \n\n### Workaround\n\nThere is no known workaround at this time.\n\n### Resolution\n\nAll TigerVNC users should upgrade to the latest version:\n \n \n # emerge --sync\n # emerge --ask --oneshot --verbose \">=net-misc/tigervnc-1.7.1\"", "published": "2017-02-20T00:00:00", "cvss": {"score": 0.0, "vector": "NONE"}, "href": "https://security.gentoo.org/glsa/201702-19", "cvelist": ["CVE-2017-5581"], "lastseen": "2017-02-21T01:00:00"}, {"id": "GLSA-201801-13", "type": "gentoo", "title": "TigerVNC: Multiple vulnerabilities", "description": "### Background\n\nTigerVNC is a high-performance VNC server/client.\n\n### Description\n\nMultiple vulnerabilities have been discovered in TigerVNC. Please review the referenced CVE Identifiers for details. \n\n### Impact\n\nAn attacker could execute arbitrary code or cause a Denial of Service condition. \n\n### Workaround\n\nThere is no known workaround at this time.\n\n### Resolution\n\nAll TigerVNC users should upgrade to the latest version:\n \n \n # emerge --sync\n # emerge --ask --oneshot --verbose \">=net-misc/tigervnc-1.8.0\"", "published": "2018-01-11T00:00:00", "cvss": {"score": 6.5, "vector": "AV:NETWORK/AC:LOW/Au:SINGLE_INSTANCE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://security.gentoo.org/glsa/201801-13", "cvelist": ["CVE-2016-10207", "CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7392", "CVE-2017-7395", "CVE-2017-7396"], "lastseen": "2018-01-12T03:22:04"}], "nessus": [{"id": "GENTOO_GLSA-201702-19.NASL", "type": "nessus", "title": "GLSA-201702-19 : TigerVNC: Buffer overflow", "description": "The remote host is affected by the vulnerability described in GLSA-201702-19 (TigerVNC: Buffer overflow)\n\n A buffer overflow vulnerability in ModifiablePixelBuffer::fillRect in vncviewer was found.\n Impact :\n\n A remote attacker, utilizing a malicious VNC server, could execute arbitrary code with the privileges of the user running the client or cause a Denial of Service condition.\n Workaround :\n\n There is no known workaround at this time.", "published": "2017-02-21T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://www.tenable.com/plugins/index.php?view=single&id=97262", "cvelist": ["CVE-2017-5581"], "lastseen": "2017-10-29T13:44:26"}, {"id": "SL_20170321_TIGERVNC_ON_SL6_X.NASL", "type": "nessus", "title": "Scientific Linux Security Update : tigervnc on SL6.x i386/x86_64", "description": "Security Fix(es) :\n\n - A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)\n\n - A buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service. (CVE-2017-5581)", "published": "2017-04-06T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://www.tenable.com/plugins/index.php?view=single&id=99227", "cvelist": ["CVE-2017-5581", "CVE-2016-10207"], "lastseen": "2017-10-29T13:40:58"}, {"id": "ORACLELINUX_ELSA-2017-0630.NASL", "type": "nessus", "title": "Oracle Linux 6 : tigervnc (ELSA-2017-0630)", "description": "From Red Hat Security Advisory 2017:0630 :\n\nAn update for tigervnc is now available for Red Hat Enterprise Linux 6.\n\nRed Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.\n\nVirtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients. The tigervnc packages contain a client which allows users to connect to other desktops running a VNC server.\n\nSecurity Fix(es) :\n\n* A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)\n\n* A buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service.\n(CVE-2017-5581)\n\nAdditional Changes :\n\nFor detailed information on changes in this release, see the Red Hat Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9 Technical Notes linked from the References section.", "published": "2017-03-30T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://www.tenable.com/plugins/index.php?view=single&id=99065", "cvelist": ["CVE-2017-5581", "CVE-2016-10207"], "lastseen": "2017-10-29T13:40:31"}, {"id": "CENTOS_RHSA-2017-0630.NASL", "type": "nessus", "title": "CentOS 6 : tigervnc (CESA-2017:0630)", "description": "An update for tigervnc is now available for Red Hat Enterprise Linux 6.\n\nRed Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.\n\nVirtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients. The tigervnc packages contain a client which allows users to connect to other desktops running a VNC server.\n\nSecurity Fix(es) :\n\n* A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)\n\n* A buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service.\n(CVE-2017-5581)\n\nAdditional Changes :\n\nFor detailed information on changes in this release, see the Red Hat Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9 Technical Notes linked from the References section.", "published": "2017-03-27T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://www.tenable.com/plugins/index.php?view=single&id=97953", "cvelist": ["CVE-2017-5581", "CVE-2016-10207"], "lastseen": "2017-10-29T13:40:12"}, {"id": "REDHAT-RHSA-2017-0630.NASL", "type": "nessus", "title": "RHEL 6 : tigervnc (RHSA-2017:0630)", "description": "An update for tigervnc is now available for Red Hat Enterprise Linux 6.\n\nRed Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.\n\nVirtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients. The tigervnc packages contain a client which allows users to connect to other desktops running a VNC server.\n\nSecurity Fix(es) :\n\n* A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)\n\n* A buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service.\n(CVE-2017-5581)\n\nAdditional Changes :\n\nFor detailed information on changes in this release, see the Red Hat Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9 Technical Notes linked from the References section.", "published": "2017-03-22T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://www.tenable.com/plugins/index.php?view=single&id=97876", "cvelist": ["CVE-2017-5581", "CVE-2016-10207"], "lastseen": "2017-10-29T13:35:26"}, {"id": "EULEROS_SA-2017-1227.NASL", "type": "nessus", "title": "EulerOS 2.0 SP1 : tigervnc (EulerOS-SA-2017-1227)", "description": "According to the versions of the tigervnc packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :\n\n - A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)\n\n - A double free flaw was found in the way TigerVNC handled ClientFence messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientFence messages, resulting in denial of service. (CVE-2017-7393)\n\n - A missing input sanitization flaw was found in the way TigerVNC handled credentials. A remote unauthenticated attacker could use this flaw to make Xvnc crash by sending specially crafted usernames, resulting in denial of service. (CVE-2017-7394)\n\n - An integer overflow flaw was found in the way TigerVNC handled ClientCutText messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientCutText messages, resulting in denial of service. (CVE-2017-7395)\n\n - A buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service.\n (CVE-2017-5581)\n\n - A memory leak flaw was found in the way TigerVNC handled termination of VeNCrypt connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion. (CVE-2017-7392)\n\n - A memory leak flaw was found in the way TigerVNC handled client connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion.\n (CVE-2017-7396)\n\nNote that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.", "published": "2017-09-11T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://www.tenable.com/plugins/index.php?view=single&id=103085", "cvelist": ["CVE-2017-5581", "CVE-2016-10207", "CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7392", "CVE-2017-7395", "CVE-2017-7396"], "lastseen": "2017-10-29T13:38:07"}, {"id": "ALA_ALAS-2017-879.NASL", "type": "nessus", "title": "Amazon Linux AMI : tigervnc (ALAS-2017-879)", "description": "Buffer overflow in ModifiablePixelBuffer::fillRect\n\nA buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service.\n(CVE-2017-5581)\n\nVNC server can crash when TLS handshake terminates early :\n\nA denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)\n\nSSecurityVeNCrypt memory leak :\n\nA memory leak flaw was found in the way TigerVNC handled termination of VeNCrypt connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion.\n(CVE-2017-7392)\n\nDouble free via crafted fences :\n\nA double free flaw was found in the way TigerVNC handled ClientFence messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientFence messages, resulting in denial of service. (CVE-2017-7393)\n\nServer crash via long usernames :\n\nA missing input sanitization flaw was found in the way TigerVNC handled credentials. A remote unauthenticated attacker could use this flaw to make Xvnc crash by sending specially crafted usernames, resulting in denial of service. (CVE-2017-7394)\n\nInteger overflow in SMsgReader::readClientCutText :\n\nAn integer overflow flaw was found in the way TigerVNC handled ClientCutText messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientCutText messages, resulting in denial of service.\n(CVE-2017-7395)\n\nSecurityServer and ClientServer memory leaks :\n\nA memory leak flaw was found in the way TigerVNC handled client connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion. (CVE-2017-7396)", "published": "2017-09-01T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://www.tenable.com/plugins/index.php?view=single&id=102867", "cvelist": ["CVE-2017-5581", "CVE-2016-10207", "CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7392", "CVE-2017-7395", "CVE-2017-7396"], "lastseen": "2017-10-29T13:36:06"}, {"id": "EULEROS_SA-2017-1228.NASL", "type": "nessus", "title": "EulerOS 2.0 SP2 : tigervnc (EulerOS-SA-2017-1228)", "description": "According to the versions of the tigervnc packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :\n\n - A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)\n\n - A double free flaw was found in the way TigerVNC handled ClientFence messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientFence messages, resulting in denial of service. (CVE-2017-7393)\n\n - A missing input sanitization flaw was found in the way TigerVNC handled credentials. A remote unauthenticated attacker could use this flaw to make Xvnc crash by sending specially crafted usernames, resulting in denial of service. (CVE-2017-7394)\n\n - An integer overflow flaw was found in the way TigerVNC handled ClientCutText messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientCutText messages, resulting in denial of service. (CVE-2017-7395)\n\n - A buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service.\n (CVE-2017-5581)\n\n - A memory leak flaw was found in the way TigerVNC handled termination of VeNCrypt connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion. (CVE-2017-7392)\n\n - A memory leak flaw was found in the way TigerVNC handled client connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion.\n (CVE-2017-7396)\n\nNote that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.", "published": "2017-09-11T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://www.tenable.com/plugins/index.php?view=single&id=103086", "cvelist": ["CVE-2017-5581", "CVE-2016-10207", "CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7392", "CVE-2017-7395", "CVE-2017-7396"], "lastseen": "2017-10-29T13:45:22"}, {"id": "REDHAT-RHSA-2017-2000.NASL", "type": "nessus", "title": "RHEL 7 : tigervnc and fltk (RHSA-2017:2000)", "description": "An update for tigervnc and fltk is now available for Red Hat Enterprise Linux 7.\n\nRed Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.\n\nVirtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients which allows users to connect to other desktops running a VNC server.\n\nFLTK (pronounced 'fulltick') is a cross-platform C++ GUI toolkit. It provides modern GUI functionality without the bloat, and supports 3D graphics via OpenGL and its built-in GLUT emulation.\n\nThe following packages have been upgraded to a later upstream version:\ntigervnc (1.8.0), fltk (1.3.4). (BZ#1388620, BZ#1413598)\n\nSecurity Fix(es) :\n\n* A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)\n\n* A double free flaw was found in the way TigerVNC handled ClientFence messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientFence messages, resulting in denial of service. (CVE-2017-7393)\n\n* A missing input sanitization flaw was found in the way TigerVNC handled credentials. A remote unauthenticated attacker could use this flaw to make Xvnc crash by sending specially crafted usernames, resulting in denial of service. (CVE-2017-7394)\n\n* An integer overflow flaw was found in the way TigerVNC handled ClientCutText messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientCutText messages, resulting in denial of service.\n(CVE-2017-7395)\n\n* A buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service.\n(CVE-2017-5581)\n\n* A memory leak flaw was found in the way TigerVNC handled termination of VeNCrypt connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion.\n(CVE-2017-7392)\n\n* A memory leak flaw was found in the way TigerVNC handled client connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion. (CVE-2017-7396)\n\nAdditional Changes :\n\nFor detailed information on changes in this release, see the Red Hat Enterprise Linux 7.4 Release Notes linked from the References section.", "published": "2017-08-02T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://www.tenable.com/plugins/index.php?view=single&id=102109", "cvelist": ["CVE-2017-5581", "CVE-2016-10207", "CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7392", "CVE-2017-7395", "CVE-2017-7396"], "lastseen": "2017-10-29T13:36:00"}, {"id": "ORACLELINUX_ELSA-2017-2000.NASL", "type": "nessus", "title": "Oracle Linux 7 : fltk / tigervnc (ELSA-2017-2000)", "description": "From Red Hat Security Advisory 2017:2000 :\n\nAn update for tigervnc and fltk is now available for Red Hat Enterprise Linux 7.\n\nRed Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.\n\nVirtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients which allows users to connect to other desktops running a VNC server.\n\nFLTK (pronounced 'fulltick') is a cross-platform C++ GUI toolkit. It provides modern GUI functionality without the bloat, and supports 3D graphics via OpenGL and its built-in GLUT emulation.\n\nThe following packages have been upgraded to a later upstream version:\ntigervnc (1.8.0), fltk (1.3.4). (BZ#1388620, BZ#1413598)\n\nSecurity Fix(es) :\n\n* A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)\n\n* A double free flaw was found in the way TigerVNC handled ClientFence messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientFence messages, resulting in denial of service. (CVE-2017-7393)\n\n* A missing input sanitization flaw was found in the way TigerVNC handled credentials. A remote unauthenticated attacker could use this flaw to make Xvnc crash by sending specially crafted usernames, resulting in denial of service. (CVE-2017-7394)\n\n* An integer overflow flaw was found in the way TigerVNC handled ClientCutText messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientCutText messages, resulting in denial of service.\n(CVE-2017-7395)\n\n* A buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service.\n(CVE-2017-5581)\n\n* A memory leak flaw was found in the way TigerVNC handled termination of VeNCrypt connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion.\n(CVE-2017-7392)\n\n* A memory leak flaw was found in the way TigerVNC handled client connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion. (CVE-2017-7396)\n\nAdditional Changes :\n\nFor detailed information on changes in this release, see the Red Hat Enterprise Linux 7.4 Release Notes linked from the References section.", "published": "2017-08-09T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://www.tenable.com/plugins/index.php?view=single&id=102293", "cvelist": ["CVE-2017-5581", "CVE-2016-10207", "CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7392", "CVE-2017-7395", "CVE-2017-7396"], "lastseen": "2017-10-29T13:41:43"}], "redhat": [{"id": "RHSA-2017:0630", "type": "redhat", "title": "(RHSA-2017:0630) Moderate: tigervnc security and bug fix update", "description": "Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients. The tigervnc packages contain a client which allows users to connect to other desktops running a VNC server.\n\nSecurity Fix(es):\n\n* A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)\n\n* A buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service. (CVE-2017-5581)\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Red Hat Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9 Technical Notes linked from the References section.", "published": "2017-03-21T10:17:44", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://access.redhat.com/errata/RHSA-2017:0630", "cvelist": ["CVE-2017-5581", "CVE-2016-10207"], "lastseen": "2017-03-21T09:19:44"}, {"id": "RHSA-2017:2000", "type": "redhat", "title": "(RHSA-2017:2000) Moderate: tigervnc and fltk security, bug fix, and enhancement update", "description": "Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients which allows users to connect to other desktops running a VNC server.\n\nFLTK (pronounced \"fulltick\") is a cross-platform C++ GUI toolkit. It provides modern GUI functionality without the bloat, and supports 3D graphics via OpenGL and its built-in GLUT emulation.\n\nThe following packages have been upgraded to a later upstream version: tigervnc (1.8.0), fltk (1.3.4). (BZ#1388620, BZ#1413598)\n\nSecurity Fix(es):\n\n* A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)\n\n* A double free flaw was found in the way TigerVNC handled ClientFence messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientFence messages, resulting in denial of service. (CVE-2017-7393)\n\n* A missing input sanitization flaw was found in the way TigerVNC handled credentials. A remote unauthenticated attacker could use this flaw to make Xvnc crash by sending specially crafted usernames, resulting in denial of service. (CVE-2017-7394)\n\n* An integer overflow flaw was found in the way TigerVNC handled ClientCutText messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientCutText messages, resulting in denial of service. (CVE-2017-7395)\n\n* A buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service. (CVE-2017-5581)\n\n* A memory leak flaw was found in the way TigerVNC handled termination of VeNCrypt connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion. (CVE-2017-7392)\n\n* A memory leak flaw was found in the way TigerVNC handled client connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion. (CVE-2017-7396)\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Red Hat Enterprise Linux 7.4 Release Notes linked from the References section.", "published": "2017-08-01T09:57:15", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://access.redhat.com/errata/RHSA-2017:2000", "cvelist": ["CVE-2016-10207", "CVE-2017-5581", "CVE-2017-7392", "CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7395", "CVE-2017-7396"], "lastseen": "2017-08-31T03:32:10"}], "openvas": [{"id": "OPENVAS:1361412562310871777", "type": "openvas", "title": "RedHat Update for tigervnc RHSA-2017:0630-01", "description": "Check the version of tigervnc", "published": "2017-03-22T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "http://plugins.openvas.org/nasl.php?oid=1361412562310871777", "cvelist": ["CVE-2017-5581", "CVE-2016-10207"], "lastseen": "2017-07-27T10:57:10"}, {"id": "OPENVAS:1361412562310871851", "type": "openvas", "title": "RedHat Update for tigervnc and fltk RHSA-2017:2000-01", "description": "Check the version of tigervnc and fltk", "published": "2017-08-04T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "http://plugins.openvas.org/nasl.php?oid=1361412562310871851", "cvelist": ["CVE-2017-5581", "CVE-2016-10207", "CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7392", "CVE-2017-7395", "CVE-2017-7396"], "lastseen": "2017-08-21T11:27:12"}, {"id": "OPENVAS:1361412562310851488", "type": "openvas", "title": "SuSE Update for tigervnc openSUSE-SU-2017:0444-1 (tigervnc)", "description": "Check the version of tigervnc", "published": "2017-02-11T00:00:00", "cvss": {"score": 5.0, "vector": "AV:NETWORK/AC:LOW/Au:NONE/C:NONE/I:NONE/A:PARTIAL/"}, "href": "http://plugins.openvas.org/nasl.php?oid=1361412562310851488", "cvelist": ["CVE-2016-10207"], "lastseen": "2017-12-12T11:22:52"}, {"id": "OPENVAS:1361412562310872618", "type": "openvas", "title": "Fedora Update for tigervnc FEDORA-2017-a66ca10c22", "description": "Check the version of tigervnc", "published": "2017-04-26T00:00:00", "cvss": {"score": 6.5, "vector": "AV:NETWORK/AC:LOW/Au:SINGLE_INSTANCE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "http://plugins.openvas.org/nasl.php?oid=1361412562310872618", "cvelist": ["CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7392", "CVE-2017-7395", "CVE-2017-7396"], "lastseen": "2017-07-25T10:57:23"}, {"id": "OPENVAS:1361412562310872549", "type": "openvas", "title": "Fedora Update for tigervnc FEDORA-2017-51979161f4", "description": "Check the version of tigervnc", "published": "2017-04-07T00:00:00", "cvss": {"score": 6.5, "vector": "AV:NETWORK/AC:LOW/Au:SINGLE_INSTANCE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "http://plugins.openvas.org/nasl.php?oid=1361412562310872549", "cvelist": ["CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7392", "CVE-2017-7395", "CVE-2017-7396"], "lastseen": "2017-07-25T10:57:35"}], "oraclelinux": [{"id": "ELSA-2017-0630", "type": "oraclelinux", "title": "tigervnc security and bug fix update", "description": "[1.1.0-24]\n- Proper global init/deinit of GnuTLS\n Resolves: bz#1418946\n[1.1.0-23]\n- Fix buffer overflow in FullFramePixelBuffer::fillRect\n Resolves: bz#1416289\n[1.1.0-22]\n- Fix buffer overflow in FullFramePixelBuffer::fillRect\n Resolves: bz#1416289\n[1.1.0-21]\n- Enable DRI2 and DRI3\n Resolves: bz#1323065\n[1.1.0-20]\n- Rebuild against fixed xorg-x11-server to avoid automatical disconnects\n when initiazed from xinetd\n Resolves: bz#1390458\n[1.1.0-19]\n- Restore default behaviour to listen on TCP\n Resolves: bz#1378922", "published": "2017-03-27T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "http://linux.oracle.com/errata/ELSA-2017-0630.html", "cvelist": ["CVE-2017-5581", "CVE-2016-10207"], "lastseen": "2017-03-27T21:17:44"}, {"id": "ELSA-2017-2000", "type": "oraclelinux", "title": "tigervnc and fltk security, bug fix, and enhancement update", "description": "fltk\n[1.3.4-1]\n- Re-base to 1.3.4 (+ sync with Fedora)\ntigervnc\n[1.8.0-1]\n- Update to 1.8.0\n Resolves: bz#1388620\n[1.7.90-2]\n- Make RandR callbacks optional\n Resolves: bz#1444948\n[1.7.90-1]\n- Update to 1.7.90\n Resolves: bz#1388620\n[1.7.1-3]\n- Delete underlying ssecurity in SSecurityVeNCrypt [CCVE-2017-7392]\n Resolves: bz#1439127\n Prevent double free by crafted fences [CVE-2017-7393]\n Resolves: bz#1439134\n[1.7.1-2]\n- Be more restrictive with shared memory mode bits\n Resolves: bz#1152552\n Limit max username/password size in SSecurityPlain [CVE-2017-7394]\n Resolves: bz#1438737\n Fix crash from integer overflow in SMsgReader::readClientCutText [CVE-2017-7395]\n Resolves: bz#1438742\n[1.7.1-1]\n- Update to 1.7.1\n Resolves: bz#1388620\n Resolves: bz#1343899\n Resolves: bz#1410164\n Resolves: bz#1415547\n Resolves: bz#1418945\n Resolves: bz#1416290\n Resolves: bz#1342956\n- Fix shared memory leakage\n Resolves: bz#1358090\n- Added systemd unit file for xvnc\n Resolves: bz#1393971", "published": "2017-08-07T00:00:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "http://linux.oracle.com/errata/ELSA-2017-2000.html", "cvelist": ["CVE-2017-5581", "CVE-2016-10207", "CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7392", "CVE-2017-7395", "CVE-2017-7396"], "lastseen": "2017-08-08T04:20:23"}], "centos": [{"id": "CESA-2017:0630", "type": "centos", "title": "tigervnc security update", "description": "**CentOS Errata and Security Advisory** CESA-2017:0630\n\n\nVirtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients. The tigervnc packages contain a client which allows users to connect to other desktops running a VNC server.\n\nSecurity Fix(es):\n\n* A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)\n\n* A buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service. (CVE-2017-5581)\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Red Hat Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9 Technical Notes linked from the References section.\n\n**Merged security bulletin from advisories:**\nhttp://lists.centos.org/pipermail/centos-cr-announce/2017-March/003960.html\n\n**Affected packages:**\ntigervnc\ntigervnc-server\ntigervnc-server-applet\ntigervnc-server-module\n\n**Upstream details at:**\nhttps://rhn.redhat.com/errata/RHSA-2017-0630.html", "published": "2017-03-24T15:45:43", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "http://lists.centos.org/pipermail/centos-cr-announce/2017-March/003960.html", "cvelist": ["CVE-2017-5581", "CVE-2016-10207"], "lastseen": "2017-10-03T18:25:12"}, {"id": "CESA-2017:2000", "type": "centos", "title": "fltk, tigervnc security update", "description": "**CentOS Errata and Security Advisory** CESA-2017:2000\n\n\nVirtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients which allows users to connect to other desktops running a VNC server.\n\nFLTK (pronounced \"fulltick\") is a cross-platform C++ GUI toolkit. It provides modern GUI functionality without the bloat, and supports 3D graphics via OpenGL and its built-in GLUT emulation.\n\nThe following packages have been upgraded to a later upstream version: tigervnc (1.8.0), fltk (1.3.4). (BZ#1388620, BZ#1413598)\n\nSecurity Fix(es):\n\n* A denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. (CVE-2016-10207)\n\n* A double free flaw was found in the way TigerVNC handled ClientFence messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientFence messages, resulting in denial of service. (CVE-2017-7393)\n\n* A missing input sanitization flaw was found in the way TigerVNC handled credentials. A remote unauthenticated attacker could use this flaw to make Xvnc crash by sending specially crafted usernames, resulting in denial of service. (CVE-2017-7394)\n\n* An integer overflow flaw was found in the way TigerVNC handled ClientCutText messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientCutText messages, resulting in denial of service. (CVE-2017-7395)\n\n* A buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service. (CVE-2017-5581)\n\n* A memory leak flaw was found in the way TigerVNC handled termination of VeNCrypt connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion. (CVE-2017-7392)\n\n* A memory leak flaw was found in the way TigerVNC handled client connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion. (CVE-2017-7396)\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Red Hat Enterprise Linux 7.4 Release Notes linked from the References section.\n\n**Merged security bulletin from advisories:**\nhttp://lists.centos.org/pipermail/centos-cr-announce/2017-August/004110.html\nhttp://lists.centos.org/pipermail/centos-cr-announce/2017-August/004573.html\n\n**Affected packages:**\nfltk\nfltk-devel\nfltk-fluid\nfltk-static\ntigervnc\ntigervnc-icons\ntigervnc-license\ntigervnc-server\ntigervnc-server-applet\ntigervnc-server-minimal\ntigervnc-server-module\n\n**Upstream details at:**\n", "published": "2017-08-24T01:37:02", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "http://lists.centos.org/pipermail/centos-cr-announce/2017-August/004110.html", "cvelist": ["CVE-2017-5581", "CVE-2016-10207", "CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7392", "CVE-2017-7395", "CVE-2017-7396"], "lastseen": "2017-10-03T18:24:24"}], "amazon": [{"id": "ALAS-2017-879", "type": "amazon", "title": "Medium: tigervnc", "description": "**Issue Overview:**\n\nBuffer overflow in ModifiablePixelBuffer::fillRect \nA buffer overflow flaw, leading to memory corruption, was found in TigerVNC viewer. A remote malicious VNC server could use this flaw to crash the client vncviewer process resulting in denial of service. ([CVE-2017-5581 __](<https://access.redhat.com/security/cve/CVE-2017-5581>))\n\nVNC server can crash when TLS handshake terminates early: \nA denial of service flaw was found in the TigerVNC's Xvnc server. A remote unauthenticated attacker could use this flaw to make Xvnc crash by terminating the TLS handshake process early. ([CVE-2016-10207 __](<https://access.redhat.com/security/cve/CVE-2016-10207>))\n\nSSecurityVeNCrypt memory leak: \nA memory leak flaw was found in the way TigerVNC handled termination of VeNCrypt connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion. ([CVE-2017-7392 __](<https://access.redhat.com/security/cve/CVE-2017-7392>))\n\nDouble free via crafted fences: \nA double free flaw was found in the way TigerVNC handled ClientFence messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientFence messages, resulting in denial of service. ([CVE-2017-7393 __](<https://access.redhat.com/security/cve/CVE-2017-7393>))\n\nServer crash via long usernames: \nA missing input sanitization flaw was found in the way TigerVNC handled credentials. A remote unauthenticated attacker could use this flaw to make Xvnc crash by sending specially crafted usernames, resulting in denial of service. ([CVE-2017-7394 __](<https://access.redhat.com/security/cve/CVE-2017-7394>))\n\nInteger overflow in SMsgReader::readClientCutText: \nAn integer overflow flaw was found in the way TigerVNC handled ClientCutText messages. A remote, authenticated attacker could use this flaw to make Xvnc crash by sending specially crafted ClientCutText messages, resulting in denial of service. ([CVE-2017-7395 __](<https://access.redhat.com/security/cve/CVE-2017-7395>))\n\nSecurityServer and ClientServer memory leaks: \nA memory leak flaw was found in the way TigerVNC handled client connections. A remote unauthenticated attacker could repeatedly send connection requests to the Xvnc server, causing it to consume large amounts of memory resources over time, and ultimately leading to a denial of service due to memory exhaustion. ([CVE-2017-7396 __](<https://access.redhat.com/security/cve/CVE-2017-7396>))\n\n \n**Affected Packages:** \n\n\ntigervnc\n\n \n**Issue Correction:** \nRun _yum update tigervnc_ to update your system. \n\n\n \n**New Packages:**\n \n \n i686: \n tigervnc-debuginfo-1.8.0-1.32.amzn1.i686 \n tigervnc-server-module-1.8.0-1.32.amzn1.i686 \n tigervnc-server-1.8.0-1.32.amzn1.i686 \n tigervnc-1.8.0-1.32.amzn1.i686 \n \n src: \n tigervnc-1.8.0-1.32.amzn1.src \n \n x86_64: \n tigervnc-1.8.0-1.32.amzn1.x86_64 \n tigervnc-server-module-1.8.0-1.32.amzn1.x86_64 \n tigervnc-server-1.8.0-1.32.amzn1.x86_64 \n tigervnc-debuginfo-1.8.0-1.32.amzn1.x86_64 \n \n \n", "published": "2017-08-31T15:56:00", "cvss": {"score": 6.8, "vector": "AV:NETWORK/AC:MEDIUM/Au:NONE/C:PARTIAL/I:PARTIAL/A:PARTIAL/"}, "href": "https://alas.aws.amazon.com/ALAS-2017-879.html", "cvelist": ["CVE-2017-5581", "CVE-2016-10207", "CVE-2017-7393", "CVE-2017-7394", "CVE-2017-7392", "CVE-2017-7395", "CVE-2017-7396"], "lastseen": "2017-09-01T03:30:32"}], "suse": [{"id": "OPENSUSE-SU-2017:0444-1", "type": "suse", "title": "Security update for tigervnc (important)", "description": "This update for tigervnc fixes the following issues:\n\n This security issue was fixed:\n\n - CVE-2016-10207: Prevent crash caused by failed TLS connection\n (bnc#1023012)\n\n This non-security issue was fixed:\n\n * Fix random client disconnections (boo#1022432)\n\n", "published": "2017-02-11T03:10:12", "cvss": {"score": 0.0, "vector": "NONE"}, "href": "http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00020.html", "cvelist": ["CVE-2016-10207"], "lastseen": "2017-02-11T02:59:58"}]}}